Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
neonephos
/
guidelines-development
Public
Notifications
You must be signed in to change notification settings
Fork
4
Star
1
Code
Issues
0
Pull requests
8
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
docs: add security guidelines and SECURITY.md template
- #7
#7
Open
morri-son
wants to merge 26 commits into
neonephos:main
neonephos/guidelines-development:main
from
morri-son:add-security-docs
morri-son/guidelines-development:add-security-docs
Copy head branch name to clipboard
Conversation
Commits
26
(26)
Checks
Files changed
Open
docs: add security guidelines and SECURITY.md template
#7
morri-son
wants to merge 26 commits into
neonephos:main
neonephos/guidelines-development:main
from
morri-son:add-security-docs
morri-son/guidelines-development:add-security-docs
Copy head branch name to clipboard
Commits
Commits on Apr 7, 2026
docs: add security guidelines and SECURITY.md template
morri-son
committed
dd7f434
View commit details
Copy full SHA for dd7f434
Browse repository at this point
docs: improve practicality of security docs — make guidelines livable
Show description for d57efb1
morri-son
committed
d57efb1
View commit details
Copy full SHA for d57efb1
Browse repository at this point
docs: relax supply chain resolution timelines to match project maturity
Show description for 14f8e38
morri-son
committed
14f8e38
View commit details
Copy full SHA for 14f8e38
Browse repository at this point
Commits on Apr 9, 2026
docs: integrate PR feedback — add operational security controls, OpenSSF Scorecard, and template improvements
Show description for 9319ade
morri-son
committed
9319ade
View commit details
Copy full SHA for 9319ade
Browse repository at this point
Commits on Apr 15, 2026
docs: make vulnerability reporting platform-agnostic
Show description for 187b4b3
morri-son
committed
187b4b3
View commit details
Copy full SHA for 187b4b3
Browse repository at this point
Commits on Apr 17, 2026
docs: add container image scanning and license compliance scanning sections
Show description for 559970e
morri-son
committed
559970e
View commit details
Copy full SHA for 559970e
Browse repository at this point
docs: align security guidelines with OpenSSF Security Baseline
Show description for d7b21b0
morri-son
committed
d7b21b0
View commit details
Copy full SHA for d7b21b0
Browse repository at this point
Commits on Apr 20, 2026
docs: trim implementation details, add SLA rationale and exemplary project references
Show description for 5b7ba8d
morri-son
committed
5b7ba8d
View commit details
Copy full SHA for 5b7ba8d
Browse repository at this point
consolidate section 8, Revise introduction statement and point to OpenSSF
morri-son
committed
f22cb73
View commit details
Copy full SHA for f22cb73
Browse repository at this point
add link to openssf Vulnerability Disclosure Guide
morri-son
committed
7c60a71
View commit details
Copy full SHA for 7c60a71
Browse repository at this point
Commits on Apr 21, 2026
soften SLAs
Show description for 16f80dd
morri-son
committed
16f80dd
View commit details
Copy full SHA for 16f80dd
Browse repository at this point
Commits on Apr 23, 2026
docs: condense security guidelines from 513 to 300 lines
Show description for aa3ed56
morri-son
committed
aa3ed56
View commit details
Copy full SHA for aa3ed56
Browse repository at this point
Commits on May 5, 2026
address PR review feedback from Skarlso
Show description for 5df2757
morri-son
committed
5df2757
View commit details
Copy full SHA for 5df2757
Browse repository at this point
make push protection a MUST
morri-son
committed
1cc7269
View commit details
Copy full SHA for 1cc7269
Browse repository at this point
Commits on May 18, 2026
Update security-guidelines/security-guidelines.md
Show description for 636d843
morri-son
and
ScheererJ
authored
636d843
View commit details
Copy full SHA for 636d843
Browse repository at this point
docs: clarify security guidelines scope is dev/build/release lifecycle
Show description for f1e2f80
morrison-sap
committed
f1e2f80
View commit details
Copy full SHA for f1e2f80
Browse repository at this point
docs: spell out CVSS judgment criteria in §7
Show description for abac64e
morrison-sap
committed
abac64e
View commit details
Copy full SHA for abac64e
Browse repository at this point
docs: tie SCA scan frequency and visibility to OpenSSF Baseline
Show description for 8869bf3
morrison-sap
committed
8869bf3
View commit details
Copy full SHA for 8869bf3
Browse repository at this point
docs: anchor license allowlist to TSC + foundation licensing policy
Show description for 1de3d17
morrison-sap
committed
1de3d17
View commit details
Copy full SHA for 1de3d17
Browse repository at this point
docs: scope 2FA and deploy-key controls to SCM/CI/registry plane
Show description for 81af4ce
morrison-sap
committed
81af4ce
View commit details
Copy full SHA for 81af4ce
Browse repository at this point
docs: note Dependabot/Renovate update SHA-pinned actions automatically
Show description for ce961e1
morrison-sap
committed
ce961e1
View commit details
Copy full SHA for ce961e1
Browse repository at this point
docs: anchor org owner count and clarify repo admin role in §9.5
Show description for 62a6e76
morrison-sap
committed
62a6e76
View commit details
Copy full SHA for 62a6e76
Browse repository at this point
docs: restructure maintainer vetting criteria into numbered list
Show description for d6e7d25
morrison-sap
committed
d6e7d25
View commit details
Copy full SHA for d6e7d25
Browse repository at this point
docs: add threat-modelling references to §9.7
Show description for 0b51164
morrison-sap
committed
0b51164
View commit details
Copy full SHA for 0b51164
Browse repository at this point
docs: clarify Resolution column reference date in §10
Show description for f898ff5
morrison-sap
committed
f898ff5
View commit details
Copy full SHA for f898ff5
Browse repository at this point
docs: clarify multi-repo SECURITY.md fall-through (GitHub vs GitLab)
Show description for ff09c49
morrison-sap
committed
ff09c49
View commit details
Copy full SHA for ff09c49
Browse repository at this point
You can’t perform that action at this time.